12-08-2019, 01:22 AM
(This post was last modified: 12-08-2019, 01:42 PM by CuriousTommy.)
(12-07-2019, 10:35 PM)hmuller Wrote: In other words, how can the end user be reasonably assured that the firmware being used to update a device is in fact from the vendor and not malware? This question assumes the vendor is not publishing malicious firmware as Asus did in the past.
Can you elaborate on that? In my experience stupidly easy is not always better.
I would recommend you contact Richard Hughes if you want specific details on your concerns about LVFS.
But from I understand Richard gets in contact with the Vendor to see if they are interested in providing their frimware to the LVFS. Those frimware files comes from the vendors that want to add it.
Edit: This section confirms it.